Description
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11086431; Issue ID: MSV-8189.
Published: 2026-08-03
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing permission check in the Telephony component of MediaTek chipsets can allow local actors to read protected data without needing additional privileges. Because the flaw does not require any prior exploitation of the device, the impact is strictly the disclosure of sensitive local information to a user or process that gains access to the vulnerable module.

Affected Systems

The vulnerability is present in MediaTek, Inc. MediaTek chipset devices that include the Telephony functionality. No specific build or firmware versions are listed, so any system that incorporates the affected Telephony component is potentially exposed.

Risk and Exploitability

The CVSS score of 6.2 indicates medium severity, and the EPSS score of < 1% shows a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation reports to date. However, the flaw can be triggered locally with no user interaction, so the likelihood of exploitation depends on the presence of the vulnerable component and the attacker’s physical or local access. Using the provided patch ID and applying the vendor supplied fix will eliminate the risk.

Generated by OpenCVE AI on August 4, 2026 at 21:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Mediatek vendor patch identified by ALPS11086431 to resolve the missing permission check.
  • If an immediate patch cannot be applied, restrict or disable the Telephony functionality or enforce stricter permission checks on the device.
  • Monitor device logs for suspicious Telephony access attempts to detect potential local information disclosure before a patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 21:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title MediaTek Telephony Permission Check Failure Leading to Local Information Disclosure

Mon, 03 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11086431; Issue ID: MSV-8189.
Weaknesses CWE-926
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-08-03T19:41:08.738Z

Reserved: 2025-11-03T01:30:59.015Z

Link: CVE-2026-20470

cve-icon Vulnrichment

Updated: 2026-08-03T19:41:03.539Z

cve-icon NVD

Status : Received

Published: 2026-08-03T03:16:41.940

Modified: 2026-08-03T20:17:18.920

Link: CVE-2026-20470

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:00:07Z

Weaknesses
  • CWE-926

    Improper Export of Android Application Components